Trust-based security level evaluation using Bayesian belief networks

  • Authors:
  • Siv Hilde Houmb;Indrakshi Ray;Indrajit Ray;Sudip Chakraborty

  • Affiliations:
  • SecureNOK Ltd.;Colorado State University;Colorado State University;Valdosta State University

  • Venue:
  • Transactions on computational science X
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security is not merely about technical solutions and patching vulnerabilities. Security is about trade-offs and adhering to realistic security needs, employed to support core business processes. Also, modern systems are subject to a highly competitive market, often demanding rapid development cycles, short life-time, short time-to-market, and small budgets. Security evaluation standards, such as ISO 14508 Common Criteria and ISO/IEC 27002, are not adequate for evaluating the security of many modern systems for resource limitations, time-tomarket, and other constraints. Towards this end, we propose an alternative time and cost effective approach for evaluating the security level of a security solution, system or part thereof. Our approach relies on collecting information from different sources, who are trusted to varying degrees, and on using a trust measure to aggregate available information when deriving security level. Our approach is quantitative and implemented as a Bayesian Belief Network (BBN) topology, allowing us to reason over uncertain information and seemingly aggregating disparate information. We illustrate our approach by deriving the security level of two alternative Denial of Service (DoS) solutions. Our approach can also be used in the context of security solution trade-off analysis.